Security
How League Aura protects league data
Early Access security statement · 4 August 2026
Role-based access
League workspaces use authenticated accounts and role-based server checks. Chairman, Vice Chairman, Finemaster, Accountant and manager permissions are enforced by the application API, not only by hidden buttons.
Private storage and secrets
Manager portraits are kept in private storage. Service-role keys, email keys and other secrets remain on the server and are not included in browser code.
Transport and browser protection
Production traffic uses HTTPS. League Aura applies strict transport, framing, content-type, referrer, permissions and content-security headers to reduce common browser attacks.
Data minimisation
League Aura does not require an FPL password. Public fantasy data is combined only with the optional profile, access and email details required to provide the service.
Monitoring and recovery
Platform administration tracks failed automations, email failures, stale data, analytics jobs and capacity thresholds. Security-sensitive changes and access problems are investigated using limited operational logs.
Your account
Use a unique password and protect the email or Google account used to sign in. League administrators should enable multi-factor authentication on their email accounts and on any connected development services.
Responsible disclosure
Do not access data that is not yours or disrupt the service. Report a suspected vulnerability privately through Support with the page, steps and impact. We will acknowledge legitimate reports and prioritise risks affecting account or cross-league access.
Report a concern